MEDIUM6.5
GHSA-mmwx-rj87-vfgr
DNSJava affected by KeyTrap - NSEC3 closest encloser proof can exhaust CPU resources
Quick fix
GHSA-mmwx-rj87-vfgr — dnsjava:dnsjava: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.6.0</version> for dnsjava:dnsjavaDetails
### Impact Users using the `ValidatingResolver` for DNSSEC validation can run into CPU exhaustion with specially crafted DNSSEC-signed zones.
### Patches Users should upgrade to dnsjava v3.6.0
### Workarounds Although not recommended, only using a non-validating resolver, will remove the vulnerability.
### References https://www.athene-center.de/en/keytrap
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/dnsjava:dnsjava
Introduced in:
3.5.0Fixed in: 3.6.0Fix
# pom.xml: bump <version>3.6.0</version> for dnsjava:dnsjavaMaven/org.jitsi:dnssecjava
Introduced in:
0No fixed version published yet for org.jitsi:dnssecjava (maven). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/dnsjava/dnsjava/security/advisories/GHSA-mmwx-rj87-vfgr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-50868[ADVISORY]
- https://github.com/dnsjava/dnsjava/commit/711af79be3214f52daa5c846b95766dc0a075116[WEB]
- https://github.com/advisories/GHSA-pv4h-p8jr-6cv2[ADVISORY]
- https://github.com/dnsjava/dnsjava[PACKAGE]